PT-2026-33823 · Openclaw · Openclaw
Zou Dikai
·
Published
2026-04-17
·
Updated
2026-04-21
·
CVE-2026-41389
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenClaw versions 2026.4.7 through 2026.4.14
Description
Failure to enforce local-root containment on tool-result media paths allows arbitrary local and UNC (Universal Naming Convention, a standard for specifying network shares) file access. Attackers can craft malicious tool-result media references to trigger host-side file reads or Windows network path access, potentially disclosing sensitive files or exposing credentials.
Recommendations
Update to version 2026.4.15.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openclaw